MGASA-2019-0241
Dashboard / Vulnerabilities / MGASA-2019-0241
MGASA-2019-0241
Summary: Updated java-1.8.0-openjdk packages fix security vulnerabilities
Details: The updated packages fix several bugs and some security issues: Side-channel attack risks in Elliptic Curve (EC) cryptography. (CVE-2019-2745) Insufficient checks of suppressed exceptions in deserialization. (CVE-2019-2762) Unbounded memory allocation during deserialization in Collections. (CVE-2019-2769) Insufficient restriction of privileges in AccessController. (CVE-2019-2786) Missing URL format validation. (CVE-2019-2816) Missing array bounds check in crypto providers. (CVE-2019-2842)
References: https://advisories.mageia.org/MGASA-2019-0241.html, https://bugs.mageia.org/show_bug.cgi?id=25172, https://access.redhat.com/errata/RHSA-2019:1816, https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA
Affected packages
Package
Name: java-1.8.0-openjdk
Purl: pkg:rpm/mageia/java-1.8.0-openjdk?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
